need an idea on how to better determine a file's content/type.
here's the command-line scenario:

1. run tcpdump (or tshark, et. al.) to capture a transaction in .lpc (in this case, ftp)
2. run tcpflow to reconstruct the session
3. run "file" on appropriate, reconstructed portion (in other words, the actual data transfered).
for instance: